Files
wisp/.env.example
explewd 266f9708e3
All checks were successful
Docker / build-and-push (push) Successful in 3m9s
Implement scoped upload invites
Adds a second, narrower credential type alongside UPLOAD_PASSWORD: an
admin (ADMIN_PASSWORD-gated, /admin) can mint time-boxed, use-limited,
independently revocable invite links (?invite=<token>) that skip the
password screen for one-off sharing without handing out the master
password. Invite consumption is an atomic check-and-increment to avoid
a race on single-use invites; admin surface 503s (not boot failure)
when ADMIN_PASSWORD is unset.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 19:29:46 +02:00

15 lines
474 B
Plaintext

# Image is built and pushed by .gitea/workflows/docker.yml
IMAGE=your-registry.example.com/your-org/wisp:latest
# Public URL is fronted by a reverse proxy — this container just needs to
# listen on HOST_PORT.
HOST_PORT=3040
TTL_SECONDS=259200
MAX_UPLOAD_BYTES=209715200
UPLOAD_PASSWORD=change-me
# Optional. Unset disables the /admin invite-management page entirely
# (503, not a boot failure). Set to enable minting scoped upload invites.
ADMIN_PASSWORD=change-me-too